cbcvebase.
CVE-2020-8286
published 2020-12-14

CVE-2020-8286: curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
4.58%
90.6th percentile
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.14.610.14.6
applemac_os_x
applemac_os_x
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos>= 11.0 < 11.311.3
applemacos_big_sur
applesecurity_update_2021-002_catalina
debiancurl< curl 7.74.0-1 (bookworm)curl 7.74.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.74.0-17.74.0-1
haxxcurl>= 0 < 7.47.0-1ubuntu2.187.47.0-1ubuntu2.18
haxxcurl>= 0 < 7.58.0-2ubuntu3.127.58.0-2ubuntu3.12
haxxcurl>= 0 < 7.68.0-1ubuntu2.47.68.0-1ubuntu2.4
haxxlibcurl>= 7.41.0 < 7.74.07.74.0
httpsgithub.com_curl_curl
msrccm1_curl_7.68.0-3_on_cbl_mariner_1.0
oraclecommunications_billing_and_revenue_management
oraclecommunications_cloud_native_core_policy
oracleessbase

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.